Python package supply-chain risks for AI development
🛡️ On March 24, 2026, widely used Python package LiteLLM was compromised on PyPI, delivering a .pth-based payload that auto-executed on interpreter start. The threat actor group TeamPCP pushed malicious versions that harvested cloud tokens, SSH keys and other secrets, and poisoned packages were available for roughly three hours. The incident is part of a broader rise in malicious open-source packages and highlights unique risks in AI development environments where dependencies can expose models, data and multi-cloud credentials.
